MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9d22e63aae228eff42731d33b65a7a18d7957c4cdffedf3d9bcc8d348ec71c43. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Formbook


Vendor detections: 7


Intelligence 7 IOCs YARA 5 File information Comments

SHA256 hash: 9d22e63aae228eff42731d33b65a7a18d7957c4cdffedf3d9bcc8d348ec71c43
SHA3-384 hash: 3d8c805d393e1b4ca3bdf8a5b15aafbb153381ced656d2d273533428fb0856c11afc420237738d8719618e16fb1eba65
SHA1 hash: 9978ff1bef81ee12755ca33ee936837322fe044e
MD5 hash: 0ddd344953313a55f6eec43c4c2514c0
humanhash: north-monkey-pluto-wisconsin
File name:update SOA.rar
Download: download sample
Signature Formbook
File size:988'375 bytes
First seen:2024-09-27 07:16:59 UTC
Last seen:2024-09-27 15:21:23 UTC
File type: rar
MIME type:application/x-rar
ssdeep 24576:OkSBISJtkK5FsSELgqyIXsIVU/eZjiEwv5tjhv0qNhzV:O8SPkK7p+DytIVRVwRtTNV
TLSH T1212533DBED2A01E0364713FFE88063CBB4781495B94EE9D58860B7AD5847F8089FE758
TrID 61.5% (.RAR) RAR compressed archive (v5.0) (8000/1)
38.4% (.RAR) RAR compressed archive (gen) (5000/1)
Magika rar
Reporter cocaman
Tags:FormBook rar


Avatar
cocaman
Malicious email (T1566.001)
From: "Anna Sim - Quanterm Vn <account22.hcm@quanterm.com.vn>" (likely spoofed)
Received: "from quanterm.com.vn (unknown [45.137.22.175]) "
Date: "26 Sep 2024 11:39:58 -0700"
Subject: "SOA in AUG 2024 - QUANTERM VIETNAM & QUANTERM LOGISTICS"
Attachment: "update SOA.rar"

Intelligence


File Origin
# of uploads :
2
# of downloads :
104
Origin country :
CH CH
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:update SOA.exe
File size:1'348'327 bytes
SHA256 hash: 464fd8f90da35b3cd3bc870080feb98a1486306645f4bd341b25dae6f8a6aa7b
MD5 hash: 29fc6891a461e05e4639603562c36cc7
MIME type:application/x-dosexec
Signature Formbook
Vendor Threat Intelligence
Verdict:
Malicious
Score:
92.5%
Tags:
Encryption Shellcode Emotet Autoit Packer
Gathering data
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Backdoor.FormBook
Status:
Malicious
First seen:
2024-09-26 11:55:26 UTC
File Type:
Binary (Archive)
Extracted files:
29
AV detection:
17 of 24 (70.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  5/10
Tags:
discovery
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:AutoIt
Author:Jean-Philippe Teissier / @Jipe_
Description:AutoIT packer
Rule name:AutoIT_Compiled
Author:@bartblaze
Description:Identifies compiled AutoIT script (as EXE). This rule by itself does NOT necessarily mean the detected file is malicious.
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Formbook

rar 9d22e63aae228eff42731d33b65a7a18d7957c4cdffedf3d9bcc8d348ec71c43

(this sample)

  
Delivery method
Distributed via e-mail attachment
  
Dropping
Formbook

Comments